Is this realistic though? Every time you update a dependency you would have to read its source (and its source dependencies, and their source dependencies...)
To do that well, it would be someone's fulltime job to read and do security audits on all those dependencies.